CVE-2012-5453: SQL Injection
SQL injection vulnerability in user/indexinlineeditorsubmit.php in ATutor AContent 1.2-1 allows remote authenticated users to execute arbitrary SQL commands via the field parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-5167.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5453?
CVE-2012-5453 is classified as a medium severity vulnerability due to its potential for SQL injection.
How do I fix CVE-2012-5453?
To fix CVE-2012-5453, ensure that you apply the latest security patch or update released by ATutor for AContent version 1.2-1.
Who is affected by CVE-2012-5453?
CVE-2012-5453 affects remote authenticated users of ATutor AContent version 1.2-1.
What type of vulnerability is CVE-2012-5453?
CVE-2012-5453 is an SQL injection vulnerability.
What are the consequences of exploiting CVE-2012-5453?
Exploiting CVE-2012-5453 can allow remote authenticated users to execute arbitrary SQL commands, potentially compromising database integrity.